Healthcare
HIPAA document management for healthcare
Healthcare document management has to satisfy the HIPAA Security Rule’s technical safeguards, HITECH breach notification, and state medical record retention periods that vary from five to ten years or longer. That means recorded access to every record, encryption, unique user identification and a business associate agreement.
Why documents are difficult in healthcare
Healthcare organisations hold two very different kinds of document, and conflating them is the root of most compliance problems. Clinical records about identifiable patients carry the heaviest obligations: recorded access, minimum-necessary disclosure and retention periods set by state law rather than by federal rule. Operational documents — policies, procedures, training records, business associate agreements, incident reports — carry lighter confidentiality obligations but stricter version-control ones, because an auditor will ask which version of a procedure was in force on a specific date.
A document management system is rarely the system of record for clinical data; the EHR is. What it holds is everything the EHR does not: the signed consent that arrived by fax, the referral letter scanned at reception, the policy set, the credentialing file, the business associate agreements, the incident investigation. Those documents are where breach findings and survey deficiencies concentrate, precisely because no clinical system claims them.
Regulatory pressure
Three regulatory pressures that shape the configuration
HIPAA Security Rule — technical safeguards (45 CFR §164.312)
What it requires. Unique user identification, automatic logoff, encryption and decryption, audit controls that record activity in systems containing protected health information, integrity controls, and person or entity authentication.
What it means for a document system. Shared logins are excluded outright, sessions must expire, and access to a document containing PHI has to be recorded — not just changes to it. That last point is what rules out a plain file share: a system that logs edits but not reads cannot tell you who saw a record before it was disclosed.
HIPAA Privacy Rule — minimum necessary (45 CFR §164.502(b))
What it requires. Uses and disclosures of protected health information must be limited to the minimum necessary to accomplish the intended purpose.
What it means for a document system. Permissions have to be finer than read/write. A billing clerk who needs to confirm a procedure took place does not need the clinical narrative, and a contractor reviewing a policy does not need to retain a copy — which is why preview-only permission exists as a distinct level from preview-and-download.
HITECH breach notification (45 CFR §§164.400–414)
What it requires. Notification to affected individuals, HHS and in some cases the media following discovery of a breach of unsecured protected health information, generally within 60 days.
What it means for a document system. A 60-day clock starts at discovery, and the first task is establishing scope: which records, whose, accessed by whom. An audit trail that records reads with the acting user, timestamp and document version turns that from a forensic project into a report. Encryption matters here too — properly encrypted PHI may fall outside the definition of unsecured.
Capability mapping
Five capabilities mapped to healthcare requirements
Recorded access, not just recorded change
Every view and download of a document is written to the immutable audit trail with the acting user, timestamp, source address and document version. This is the HIPAA §164.312(b) audit control in practice, and it is the capability that determines whether a breach investigation takes an afternoon or a fortnight.
Minimum-necessary permissions
Role-based access is applied per module with levels finer than read/write: preview only, upload only, preview and download, editor, or a custom combination. A role can be composed as read-everywhere-download-nothing for an external reviewer without inventing a new user type.
OCR over scanned clinical paperwork
Consents, referral letters and fax-received documentation arrive as images. OCR extracts their text so they are findable by patient identifier or referring clinician, which is what makes a record request answerable within the statutory window rather than after a manual search.
Policy version control and acknowledgement
Surveyors ask which version of a procedure was in force on a given date and who had read it. Version history answers the first; per-user acknowledgement against a specific version answers the second. Reissuing the requirement when a policy is superseded is what keeps the attestation meaningful.
Retention by record class, with legal hold
State medical record retention periods differ substantially and depend on the patient’s age at treatment. Attaching the rule to the record class rather than the folder means relocation cannot change the period, and a legal hold suspends disposal when a claim becomes reasonably anticipated.
Taxonomy
A starting folder taxonomy
Patient-associated documents
- Consents and authorisations
- Referrals and correspondence
- Scanned external records
- Release-of-information requests and responses
- Advance directives
Clinical governance
- Policies and procedures (controlled)
- Clinical guidelines and pathways
- Incident reports and investigations
- Root cause analyses
- Committee minutes
Workforce
- Credentialing and privileging files
- Licences and registrations with expiry dates
- Training and competency records
- Immunisation and fit-test records
Compliance and contracts
- Business associate agreements
- Risk analyses and remediation plans
- Breach assessments and notifications
- Payer contracts
- Accreditation evidence
Facilities and equipment
- Equipment service and calibration records
- Environmental monitoring
- Safety inspections
Patient-associated documents are the only branch holding protected health information at scale, which lets you apply the tightest permissions and the recorded-access requirement to one part of the tree rather than all of it.
Worked example
A worked workflow: policy revision and re-acknowledgement
Step 1: Draft and review
The policy owner creates a new version. It routes in parallel to the clinical lead and the compliance officer, each recording an approval or a change request with a comment.
Step 2: Approve before issue
On approval the version is locked, dated and marked current. The previous version is marked superseded and retained — never deleted, because "what was in force in March" is a question that will be asked.
Step 3: Distribute and acknowledge
Affected roles receive an acknowledgement task. Completion is recorded per named user against this specific version, and outstanding acknowledgements are visible as a list rather than a percentage.
Step 4: Schedule the next review
A review date is set before the current one lapses, and a task is raised in advance. A policy past its review date is a finding whether or not its content is still correct.
Retention
Retention expectations
| Record class | Commonly applied period | What starts the clock | Source |
|---|---|---|---|
| HIPAA compliance documentation (policies, risk analyses, BAAs) | 6 years | Later of creation date or the date it was last in effect | 45 CFR §164.316(b)(2) |
| Adult medical records | Commonly 6–10 years, longer in several states | Date of last treatment or discharge | State law — varies materially; verify per state of operation |
| Minors’ medical records | Often the adult period extended past the age of majority | Patient reaching the age of majority | State law — verify; the extension is the part most often missed |
| Medicare cost reports and supporting records | 5 years | Closure of the cost report | 42 CFR §413.24(e) |
| Occupational exposure and medical surveillance records | Duration of employment plus 30 years | End of employment | 29 CFR §1910.1020 |
| Incident reports and investigations | Aligned to the applicable statute of limitations | Date of incident or discovery | Organisational policy informed by state limitation periods |
These periods are indicative and must be confirmed against the states and countries you operate in before you rely on them. Retention is set by state law for clinical records, runs differently for minors, and is displaced entirely by a legal hold. Nothing here is legal advice.
FAQ
Healthcare document management: common questions
Does DocumentMS replace our EHR?
No, and it should not. The EHR is the system of record for clinical data. DocumentMS holds the documents the EHR does not claim: scanned consents and referrals, the controlled policy set, credentialing files, business associate agreements and incident investigations. Those are where survey deficiencies and breach findings concentrate, precisely because no clinical system owns them.
Will you sign a business associate agreement?
Yes, on every tier, and we sign it before any protected health information is uploaded rather than after. Any vendor handling PHI on your behalf is a business associate under HIPAA and must execute one, so this is a threshold question rather than a negotiating point — a vendor that hesitates on it is telling you something. Ask your account contact and it goes out as part of onboarding; until it is signed, the tenant is not configured for PHI.
How do we handle a release-of-information request?
Search across document contents and metadata to identify everything associated with the patient, apply the minimum-necessary standard to what is disclosed, and record the disclosure. Because the audit trail logs reads as well as changes, the accounting of disclosures is derived from the record rather than maintained as a separate register.
Can we restrict a document to preview only, with no download?
Yes. Preview only is a distinct permission level. It suits contractors, external reviewers and staff who need to confirm a fact without retaining a copy. It prevents download through the application; it cannot prevent someone photographing a screen, and we would not claim otherwise.
What happens when a state retention period conflicts with a patient’s erasure request?
The retention obligation generally prevails, but the decision has to be made deliberately and recorded. DocumentMS surfaces the retention rule and any legal hold at the point a deletion is attempted, so the conflict is visible before the decision rather than discovered afterwards.
Last reviewed: 2026-09-01. Compare all ten industry configurations.